|
270741
|
- |
|
adobe
|
air_sdk air_sdk_\&_compiler air flash_player
|
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR …
|
NVD-CWE-Other
|
CVE-2015-5566
|
2024-11-21 11:33 |
2015-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270742
|
- |
|
net-snmp
|
net-snmp
|
The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not remove the varBind variable in a netsnmp_variable_list item when parsing of the SNMP PDU fails, which allows remote at…
|
CWE-19
Data Processing Errors
|
CVE-2015-5621
|
2024-11-21 11:33 |
2015-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270743
|
- |
|
views_bulk_operations_project
|
views_bulk_operations
|
The Views Bulk Operations (VBO) module 6.x-1.x and 7.x-3.x before 7.x-3.3 for Drupal, when the bulk operation for changing Roles is enabled, allows remote authenticated users to edit user accounts an…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-5515
|
2024-11-21 11:33 |
2015-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270744
|
- |
|
migrate_project
|
migrate
|
Cross-site scripting (XSS) vulnerability in the Migrate module 7.x-2.x before 7.x-2.8 for Drupal, when the migrate_ui submodule is enabled, allows user-assisted remote attackers to inject arbitrary w…
|
CWE-79
Cross-site Scripting
|
CVE-2015-5514
|
2024-11-21 11:33 |
2015-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270745
|
- |
|
niif
|
shibboleth_authentication
|
Cross-site scripting (XSS) vulnerability in the Shibboleth authentication module 6.x-4.x before 6.x-4.2 and 7.x-4.x before 7.x-4.2 for Drupal allows remote authenticated users with the "Administer bl…
|
CWE-79
Cross-site Scripting
|
CVE-2015-5513
|
2024-11-21 11:33 |
2015-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270746
|
- |
|
me_aliases_project
|
me_aliases
|
The me aliases module 6.x-2.x before 6.x-2.10 and 7.x-1.x before 7.x-1.2 for Drupal allows remote attackers to access Views using the "me" user argument handler by substituting "me" for a user id in …
|
CWE-284
Improper Access Control
|
CVE-2015-5512
|
2024-11-21 11:33 |
2015-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270747
|
- |
|
hybridauth_social_login_project
|
hybridauth_social_login
|
The HybridAuth Social Login module 7.x-2.x before 7.x-2.13 for Drupal allows remote attackers to bypass the user registration by administrator only configuration and create an account via a social lo…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-5511
|
2024-11-21 11:33 |
2015-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270748
|
- |
|
content_construction_kit_project
|
content_construction_kit
|
Open redirect vulnerability in the Content Construction Kit (CCK) 6.x-2.x before 6.x-2.10 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via …
|
NVD-CWE-Other
|
CVE-2015-5510
|
2024-11-21 11:33 |
2015-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270749
|
- |
|
administration_views_project
|
administration_views
|
The Administration Views module 7.x-1.x before 7.x-1.4 for Drupal, when used with other unspecified modules, does not properly grant access to administration pages, which allows remote administrators…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-5509
|
2024-11-21 11:33 |
2015-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270750
|
- |
|
the_extensible_catalog_drupal_toolkit_project
|
the_extensible_catalog_drupal_toolkit
|
Cross-site request forgery (CSRF) vulnerability in the XC NCIP Provider module in the eXtensible Catalog (XC) Drupal Toolkit allows remote attackers to hijack the authentication of users with the "ad…
|
CWE-352
Origin Validation Error
|
CVE-2015-5508
|
2024-11-21 11:33 |
2015-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|